漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NamelessMC: Reactions on private or blocking profile posts can be read and modified without proper authorization
Vulnerability Description
NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. `modules/Core/queries/reactions.php` allows unauthenticated GET requests for reaction details. This means that unauthenticated visitors can read reaction participants and timestamps for private profile posts and uthenticated low-privileged users can add reactions to private or blocking profile posts. Version 2.2.5 fixes the issue.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
NamelessMC 安全漏洞
Vulnerability Description
NamelessMC是NamelessMC团队的一款免费、易于使用且功能强大的网站软件。适用于您的 Minecraft 服务器,其中包含大量功能。 NamelessMC 2.2.4版本存在安全漏洞,该漏洞源于ProfilePostReactionContext.php仅验证墙贴存在而未强制执行屏蔽或私密配置文件可见性,可能导致未经身份验证的访问者读取私密配置文件的反应参与者和时间戳,以及经过身份验证的低权限用户向私密或屏蔽配置文件添加反应。
CVSS Information
N/A
Vulnerability Type
N/A